Nexter <= 2.0.3 - Authenticated (Subscriber+) SQL Injection via 'to' and 'from'
high
The Nexter theme for WordPress is vulnerable to SQL Injection via the 'to' and 'from' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameter and lack of valid preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscri...
- CVSS:
- 8.8
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Oct 12, 2023
CVE-2023-45657 on NVD →
Nexter <= 2.0.3 - Missing Authorization
medium
The Nexter theme for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions such as nexter_extra_ext_active_ajax, nexter_extra_ext_deactivate_ajax, nexter_ext_wp_replace_url_settings_ajax, nexter_ext_wp_duplicate_post_settings_ajax, nexter_ext_save_data_ajax,...
- CVSS:
- 4.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Oct 12, 2023
CVE-2023-45658 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database